Trojan

Trojan.GenericPMF.S17946751 removal tips

Malware Removal

The Trojan.GenericPMF.S17946751 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericPMF.S17946751 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Trojan.GenericPMF.S17946751?


File Info:

name: F608DF94DB1981F97686.mlw
path: /opt/CAPEv2/storage/binaries/c7da4b93d1f49cee440d76107301b47bb5298aff82ef9adccfc93c3a8810a508
crc32: 2EA6245A
md5: f608df94db1981f97686b0c54818556b
sha1: fabf43a29cef2a4a8acd4be500d4e70b207205d0
sha256: c7da4b93d1f49cee440d76107301b47bb5298aff82ef9adccfc93c3a8810a508
sha512: 27f32f8e684e84dd0d741eeb4838c102e083e5981b0085154980af47c8eb9a870def2dfabd225faf224b2216315a0947520a9c61a18fcc1c6160684db3796703
ssdeep: 6144:plNgw6PIn1Z25C9xItZs3FWbJWiFmlHEK:Jht1Vx06UdFmJP
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B524122CF25CDFB9C87DE3B3E29AF706056BD7955D510A167B83C8362EC03805AE6624
sha3_384: e71461f090da2892e90dc5f3fa40b8525622499b0a43252a6a3231aa72e15e784dc091351f1b86c796c7a2d48034ce56
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2011-03-25 13:17:51

Version Info:

0: [No Data]

Trojan.GenericPMF.S17946751 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Trojan.GenericKD.36248848
FireEyeGeneric.mg.f608df94db1981f9
CAT-QuickHealTrojan.GenericPMF.S17946751
MalwarebytesTrojan.Dropper.BAT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005768dd1 )
K7GWTrojan ( 00577de81 )
CyrenW32/Dropper.EG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of BAT/Agent.NAS
APEXMalicious
ClamAVWin.Malware.Redcap-9828937-0
KasperskyTrojan.BAT.Agent.bbn
BitDefenderDropped:Trojan.GenericKD.36248848
AvastScript:SNH-gen [Trj]
Ad-AwareDropped:Trojan.GenericKD.36248848
SophosML/PE-A
F-SecureTrojan.TR/Redcap.osjdd
DrWebTrojan.Siggen12.42972
TrendMicroTROJ_GEN.R002C0DGO21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftDropped:Trojan.GenericKD.36248848 (B)
IkarusVirus.BAT.Agent
GDataDropped:Trojan.GenericKD.36248848
AviraTR/Redcap.osjdd
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Generic.D2291D10
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Tnega.R449412
VBA32Trojan.BAT.Agent
ALYacDropped:Trojan.GenericKD.36248848
MAXmalware (ai score=86)
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DGO21
RisingDropper.Agent!1.D197 (RDMK:cmRtazrrvi/Ud0YGCtT7IRepb93k)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.F840!tr
BitDefenderThetaGen:NN.ZexaF.34114.Ry0@aSfE0Qb
AVGScript:SNH-gen [Trj]
Cybereasonmalicious.4db198
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.GenericPMF.S17946751?

Trojan.GenericPMF.S17946751 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment